Articles Tagged “Vulnerability Management”
17 articles found

Thales Sentinel Envelope Plus: Shielding Code From AI Agents
Thales Sentinel Envelope Plus hardens compiled apps against AI reverse engineering. In tests, an AI agent found 0 of 10 bugs after using 970x more tokens.

Legit Security Agent Auto-Fixes Vulnerable Dependencies
Legit Security's agentic remediation now fixes vulnerable open-source dependencies, re-scans before and after, and opens a pull request for review.

AndroidX Security State Tracks Patches by Component
Google's AndroidX Security State 1.1.0 lets apps check three patch levels per component, covering the OS, Play system modules and the kernel LTS version.

PostgreSQL Fixes a 12-Year-Old Logical Decoding Flaw
CVE-2026-6471 let a REPLICATION-privileged user load arbitrary code. Patches shipped in PostgreSQL 18.6, 17.11, 16.15, 15.19 and 14.24 in August.

CISA Finds Decades-Old Bug Classes Still Dominate
CISA's new Vulnerability Review found stubborn weaknesses make up 41.5% of KEV entries, with input validation and injection flaws topping both lists.

Windows 11 Drops WMIC, a Longtime Malware Favorite
Microsoft has removed the WMIC command-line tool from Windows 11 24H2 and 25H2, closing a living-off-the-land binary abused by ransomware for years.

OT Vulnerability Triage Drops From Weeks to Minutes
Fortress and Industrial Defender integrated asset intelligence with AI vulnerability correlation, cutting OT vulnerability-to-asset triage to minutes.

Linux Kernel SCTP Fix Lands in All Stable Branches
An 18-year-old SCTP use-after-free went from private report to patched across every supported Linux stable branch in a little over three weeks flat.

OWASP Subtractive Security Scores What You Remove
OWASP launched a Subtractive Security Top 10 with nine platform lists and a Path Erasure Rate metric that counts attack paths deleted, not alerts raised.

Next.js Ships First Pre-Announced Security Update
Next.js patched 9 CVEs in v16.2.11 and v15.5.21 — its first pre-announced monthly security release, giving teams time to plan upgrades before disclosure.

7-Zip 26.02 Patches an Archive Decoder Flaw via ZDI
7-Zip 26.02 fixes a heap overflow in the XZ decoder, found by researcher Landon Peng and coordinated through ZDI as advisory ZDI-26-444. Update manually.

Microsoft Secure Future Initiative Hits New Milestones
Microsoft's July 2026 Secure Future Initiative report: phishing-resistant MFA on 99.97% of accounts, 732K+ resources locked down, and AI-driven defense.

CVE Lite CLI Scans npm Projects Right in Your Terminal
CVE Lite CLI, now an OWASP Incubator project, checks JavaScript lockfiles against the OSV database and suggests one-line fixes for npm, pnpm, Yarn, and Bun.

Responsible Disclosure Helps Secure Dify, an AI Platform Powering 1M+ Apps
Security researchers responsibly disclosed the DifyTap flaws in the popular Dify AI platform on June 22, 2026 — and fixes shipped quickly, protecting more than a million AI apps.

CISA's BOD 26-04 Shifts Federal Patching to a Smarter Risk-Based Model
CISA's new Binding Operational Directive 26-04 tells agencies to patch smarter, prioritizing vulnerabilities that are internet-facing, automatable, high-impact, and actively exploited.

Project Lightwell: IBM and Red Hat's $5B AI Open-Source Security Push
IBM and Red Hat launch Project Lightwell, a $5B AI-powered open-source security effort that validates fixes at scale and feeds patches upstream.

AI Browser Extensions Are Your Enterprise's Biggest Unmanaged Security Surface
LayerX's 2026 Browser Extension Security Report reveals AI extensions carry 60% more CVEs and access cookies 3x more than standard extensions — with 15% of enterprise users already exposed.
